Researchers have reported that the AI meeting minutes service 'tl;dv' had access to over 180,000 meeting metadata records, while the company explained it as 'two separate vulnerabilities.'

An independent security researcher has reported a vulnerability in '
tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open | bobdahacker
https://bobdahacker.com/blog/tldv-hack
Our View on darkreading.com Articles
https://tldv.io/ja/blog/our-thoughts-on-the-darkreading-com-article/
tl;dv is a German-based online meeting recording service that allows users to have bots participate in online meetings using Google Meet, Zoom, Microsoft Teams, and other platforms, recording and transcribing the meetings, and providing AI-powered summaries and analyses. As of January 2026, it has over 2 million users and is particularly popular among investors and sales influencer communities.

According to independent security hacker BobDaHacker, tl;dv had a vulnerability that allowed attackers to search the 'meetings' collection stored in the database by using the '
When you register with tl;dv, the platform authenticates you using a JSON Web Token (JWT) and exchanges it for a Firebase token. This token allows you to query the Firestore database. However, according to BobDaHacker, the 'meetings' collection in this database lacked tenant isolation, meaning that authenticated tl;dv users could query all meetings across all accounts on the platform. Each meeting record displays the creator's email address, meeting ID, provider, recording status, and timestamp.
Furthermore, BobDaHacker reports that for meetings with a 'waiting' status, it was possible to monitor the collection in real time, confirm the start of meeting recording, and obtain the ID, allowing attackers to join calls from people they weren't invited to. BobDaHacker claims that because there are always around 1000 meetings in the 'waiting (status: recording)' state in the collection, an attacker with a bot could simultaneously join all 1000 active calls with publicly available meeting IDs.
BobDaHacker reports that he actually used the acquired meeting IDs to participate in two online meetings. One was a Google Meet meeting related to the Malaysian Ministry of Education, which was a presentation meeting with over 157 participants. The other was a meeting of students from a major American university developing a startup app, with 21 participants, and he says that the projects under development were displayed via screen sharing.

BobDaHacker investigated Firestore's 'meetings' collection and found 181,874 meeting records belonging to 84,312 unique users, along with 35,003 email domains. Meeting metadata for government agencies in 23 countries—Brazil, Colombia, Peru, Ukraine, El Salvador, Philippines, Chile, Indonesia, Mexico, the United States, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, and Belize—as well as meetings at the University of California, Berkeley, De La Salle University in Manila, the National University of Colombia, and the University of Tokyo, were also available from the same collection. In addition, corporate meetings involving 35,000 domains were also available from an unprotected collection.
However, the meetings themselves were basically set to private, and access to the video and transcript content was not possible. On the other hand, when the privacy status of 27,334 meeting IDs was checked, more than 1,000 were set to public, and 715 inviter email addresses spanning 228 email domains were also identified.
On January 28, 2026, BobDaHacker messaged Raphael Allstat of tl;dv via LinkedIn, informing him that he had discovered a critical vulnerability that could lead to the leakage of user data. Allstat quickly replied, 'Thank you! Please report it to our Chief Technology Officer (CTO), and we will investigate immediately.' BobDaHacker then reported the vulnerability again via email and asked about compensation for reporting the vulnerability, to which Allstat replied, 'The CTO will contact you.' However, BobDaHacker says he never heard from the CTO.
BobDaHacker repeatedly inquired, but still received no response from the CTO, and Allstat continued to respond that they were 'working on a fix.' This situation continued for six months, leading BobDaHacker to disclose the tl;dv vulnerability in a blog post on August 4, 2026.

However, tl;dv's explanation states that 'a vulnerability related to access to specific conference metadata was discovered through regular evaluations by Abicom , an independent company to which tl;dv outsources penetration testing, and through responsible disclosure from an independent security researcher (BobDaHacker). Corrective measures were taken in response to these reports, and subsequent formal verification by Abicom confirmed that the vulnerability has been completely fixed,' thus indicating that the vulnerability discovered by BobDaHacker has been fixed.
On the other hand, it was newly discovered that there was another attack vector related to the same part of tl;dv's system infrastructure. In other words, while BobDaHacker pointed out that 'the reported vulnerability had not been fixed,' tl;dv explained that this did not mean that it had 'remained unfixed for six months,' but rather that there were two different attack vectors.
tl;dv has announced that it applied a patch to fix the new vulnerability within 24 hours of its discovery. Furthermore, because both incidents were related to Firebase, they have taken steps to completely remove Firebase from their system infrastructure to eliminate the possibility of similar vulnerabilities recurring.
Furthermore, tl;dv stated that the only data that could have been leaked externally was metadata such as meeting identifiers, meeting IDs, and participants' email addresses and domains, and that they 'had absolutely no access' to passwords, audio recordings, transcripts, AI-generated notes, or account and billing data. According to tl;dv, this information was not accessed through the vulnerability in question and is not stored in any accessible parts of the infrastructure.
Normally, only users with an account or those authorized to share can access a meeting, but there is also a 'URL sharing' feature that allows meetings to be shared with people without an account by providing the URL. This feature is disabled by default, and even when enabled, access is not possible without knowing the URL. However, according to tl;dv, this vulnerability made it possible to identify the 'meeting URL identifier' from the outside, which meant that hackers could obtain it in some cases. However, tl;dv explains that cases where 'third parties were able to join the meeting,' as demonstrated by BobDaHacker, are very rare, and that this only happens when the host manually approves a participation request using the URL.
In response to the report, tl;dv stated, 'Security is a critical area that needs continuous improvement on any platform. We will continue to actively invest in independent testing, respond quickly to issues discovered, and improve customer data protection. We also recognize the role that the entire cybersecurity community plays in these efforts. Moving forward, we will improve our vulnerability disclosure and response processes to ensure that all external security reports receive a timely response.'
Related Posts:
in Web Service, Security, Posted by log1e_dh







